Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 b3a980cc20394fd1…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: b1141556e7bb06fe2a9176d31a3d6237 SHA-1: 9e9f12a2d71571d44b05d69cf51d731d7c83c0ab SHA-256: b3a980cc20394fd1614f2357f688ab7c7a9d25c49452bff52bc15f23d9b30355
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves luring the user into opening the malicious attachment, which then executes the embedded payload. Further analysis of scripts or embedded objects would be required to detail the exact execution chain.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0